Skip to content

Powershell Changes For EntraID support for DataSync#29383

Open
ssubramanya wants to merge 5 commits intoAzure:mainfrom
ssubramanya:dev/subramanyamn/EntraIdPowershellSupport-v2
Open

Powershell Changes For EntraID support for DataSync#29383
ssubramanya wants to merge 5 commits intoAzure:mainfrom
ssubramanya:dev/subramanyamn/EntraIdPowershellSupport-v2

Conversation

@ssubramanya
Copy link
Copy Markdown

@ssubramanya ssubramanya commented Apr 9, 2026

Description

Note:

This is the same PR as https://github.com/Azure/azure-powershell/pull/28464 with Newer SDK used from latest swagger (after 2025-02-01-preview changes)
This is a Private Preview Feature from DataSync Point of view and Public Preview feature from Azure powershell Point of view and is being targeted to May 5th Release of powershell.
The design doc for the same can be found here
https://msdata.visualstudio.com/Database%20Systems/_git/DsMainDev/pullrequest/1801408?path=/Sql/xdb/manifest/svc/DataSync/synclibs/ClientSetup/LocalAgentSetup.wixproj&_a=files

Summary of Changes

Added UAMI Support

  • Added UAMI support for Data Sync cmdlets.
  • Introduced three new parameters across New-* and Update-* cmdlets:
    • HubDatabaseAuthenticationType
    • MemberDatabaseAuthenticationType
    • IdentityId

These parameters allow customers to:

  • Select authentication type (Password or UserAssigned)
  • Optionally provide a user-assigned identity.

Backward Compatibility

- No visible changes in behavior
- Password-based authentication continues to work without requiring new parameters.

Validation Logic

  • Password authentication
    • Requires Username and Password.
  • UserAssigned authentication
    • Requires IdentityId when creating new resources.
  • Update behavior
    • If UserAssigned is specified without IdentityId, cmdlet preserves the existing identity instead of throwing.
    • This supports partial updates intentionally.

Help and Documentation

  • Updated cmdlet help files with:
    • New parameters and their accepted values (Password, UserAssigned)
    • Examples for both password and UAMI flows.

Resource Strings

  • Added localized error messages for:
    • Missing credentials
    • Missing IdentityId
    • Invalid authentication type

Testing

Mandatory Checklist

  • SHOULD update ChangeLog.md file(s) appropriately
    • Update src/{{SERVICE}}/{{SERVICE}}/ChangeLog.md.
      • A snippet outlining the change(s) made in the PR should be written under the ## Upcoming Release header in the past tense.
    • Should not change ChangeLog.md if no new release is required, such as fixing test case only.
  • SHOULD regenerate markdown help files if there is cmdlet API change. Instruction
  • SHOULD have proper test coverage for changes in pull request.
  • SHOULD NOT adjust version of module manually in pull request

@azure-client-tools-bot-prd
Copy link
Copy Markdown

Thanks for your contribution! The pull request validation has started. Please revisit this comment for updated status.

@microsoft-github-policy-service
Copy link
Copy Markdown
Contributor

Thank you for your contribution @ssubramanya! We will review the pull request and get back to you soon.

@VeryEarly VeryEarly self-assigned this Apr 10, 2026
Comment thread ChangeLog.md Outdated
@ssubramanya
Copy link
Copy Markdown
Author

@ssubramanya please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.

@microsoft-github-policy-service agree [company="{your company}"]

Options:

  • (default - no company specified) I have sole ownership of intellectual property rights to my Submissions and I am not making Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
  • (when company given) I am making Submissions in the course of work for my employer (or my employer has intellectual property rights in my Submissions by contract or applicable law). I have permission from my employer to make Submissions and enter into this Agreement on behalf of my employer. By signing below, the defined term “You” includes me and my employer.
@microsoft-github-policy-service agree company="Microsoft"

Contributor License Agreement

@microsoft-github-policy-service agree company="Microsoft"

@ssubramanya
Copy link
Copy Markdown
Author

@ssubramanya please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.

@microsoft-github-policy-service agree [company="{your company}"]

Options:

  • (default - no company specified) I have sole ownership of intellectual property rights to my Submissions and I am not making Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
  • (when company given) I am making Submissions in the course of work for my employer (or my employer has intellectual property rights in my Submissions by contract or applicable law). I have permission from my employer to make Submissions and enter into this Agreement on behalf of my employer. By signing below, the defined term “You” includes me and my employer.
@microsoft-github-policy-service agree company="Microsoft"

Contributor License Agreement

Contribution License Agreement

This Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”), and conveys certain license rights to Microsoft Corporation and its affiliates (“Microsoft”) for Your contributions to Microsoft open source projects. This Agreement is effective as of the latest signature date below.

  1. Definitions.
    “Code” means the computer software code, whether in human-readable or machine-executable form,
    that is delivered by You to Microsoft under this Agreement.
    “Project” means any of the projects owned or managed by Microsoft and offered under a license
    approved by the Open Source Initiative (www.opensource.org).
    “Submit” is the act of uploading, submitting, transmitting, or distributing code or other content to any
    Project, including but not limited to communication on electronic mailing lists, source code control
    systems, and issue tracking systems that are managed by, or on behalf of, the Project for the purpose of
    discussing and improving that Project, but excluding communication that is conspicuously marked or
    otherwise designated in writing by You as “Not a Submission.”
    “Submission” means the Code and any other copyrightable material Submitted by You, including any
    associated comments and documentation.
  2. Your Submission. You must agree to the terms of this Agreement before making a Submission to any
    Project. This Agreement covers any and all Submissions that You, now or in the future (except as
    described in Section 4 below), Submit to any Project.
  3. Originality of Work. You represent that each of Your Submissions is entirely Your original work.
    Should You wish to Submit materials that are not Your original work, You may Submit them separately
    to the Project if You (a) retain all copyright and license information that was in the materials as You
    received them, (b) in the description accompanying Your Submission, include the phrase “Submission
    containing materials of a third party:” followed by the names of the third party and any licenses or other
    restrictions of which You are aware, and (c) follow any other instructions in the Project’s written
    guidelines concerning Submissions.
  4. Your Employer. References to “employer” in this Agreement include Your employer or anyone else
    for whom You are acting in making Your Submission, e.g. as a contractor, vendor, or agent. If Your
    Submission is made in the course of Your work for an employer or Your employer has intellectual
    property rights in Your Submission by contract or applicable law, You must secure permission from Your
    employer to make the Submission before signing this Agreement. In that case, the term “You” in this
    Agreement will refer to You and the employer collectively. If You change employers in the future and
    desire to Submit additional Submissions for the new employer, then You agree to sign a new Agreement
    and secure permission from the new employer before Submitting those Submissions.
  5. Licenses.
  • Copyright License. You grant Microsoft, and those who receive the Submission directly or
    indirectly from Microsoft, a perpetual, worldwide, non-exclusive, royalty-free, irrevocable license in the
    Submission to reproduce, prepare derivative works of, publicly display, publicly perform, and distribute
    the Submission and such derivative works, and to sublicense any or all of the foregoing rights to third
    parties.
  • Patent License. You grant Microsoft, and those who receive the Submission directly or
    indirectly from Microsoft, a perpetual, worldwide, non-exclusive, royalty-free, irrevocable license under
    Your patent claims that are necessarily infringed by the Submission or the combination of the
    Submission with the Project to which it was Submitted to make, have made, use, offer to sell, sell and
    import or otherwise dispose of the Submission alone or with the Project.
  • Other Rights Reserved. Each party reserves all rights not expressly granted in this Agreement.
    No additional licenses or rights whatsoever (including, without limitation, any implied licenses) are
    granted by implication, exhaustion, estoppel or otherwise.
  1. Representations and Warranties. You represent that You are legally entitled to grant the above
    licenses. You represent that each of Your Submissions is entirely Your original work (except as You may
    have disclosed under Section 3). You represent that You have secured permission from Your employer to
    make the Submission in cases where Your Submission is made in the course of Your work for Your
    employer or Your employer has intellectual property rights in Your Submission by contract or applicable
    law. If You are signing this Agreement on behalf of Your employer, You represent and warrant that You
    have the necessary authority to bind the listed employer to the obligations contained in this Agreement.
    You are not expected to provide support for Your Submission, unless You choose to do so. UNLESS
    REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING, AND EXCEPT FOR THE WARRANTIES
    EXPRESSLY STATED IN SECTIONS 3, 4, AND 6, THE SUBMISSION PROVIDED UNDER THIS AGREEMENT IS
    PROVIDED WITHOUT WARRANTY OF ANY KIND, INCLUDING, BUT NOT LIMITED TO, ANY WARRANTY OF
    NONINFRINGEMENT, MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE.
  2. Notice to Microsoft. You agree to notify Microsoft in writing of any facts or circumstances of which
    You later become aware that would make Your representations in this Agreement inaccurate in any
    respect.
  3. Information about Submissions. You agree that contributions to Projects and information about
    contributions may be maintained indefinitely and disclosed publicly, including Your name and other
    information that You submit with Your Submission.
  4. Governing Law/Jurisdiction. This Agreement is governed by the laws of the State of Washington, and
    the parties consent to exclusive jurisdiction and venue in the federal courts sitting in King County,
    Washington, unless no federal subject matter jurisdiction exists, in which case the parties consent to
    exclusive jurisdiction and venue in the Superior Court of King County, Washington. The parties waive all
    defenses of lack of personal jurisdiction and forum non-conveniens.
  5. Entire Agreement/Assignment. This Agreement is the entire agreement between the parties, and
    supersedes any and all prior agreements, understandings or communications, written or oral, between
    the parties relating to the subject matter hereof. This Agreement may be assigned by Microsoft.

@microsoft-github-policy-service agree company="Microsoft"

@ssubramanya ssubramanya reopened this Apr 15, 2026
@azure-pipelines
Copy link
Copy Markdown
Contributor

Azure Pipelines:
4 pipeline(s) require an authorized user to comment /azp run to run.

@VeryEarly VeryEarly closed this Apr 20, 2026
@VeryEarly VeryEarly reopened this Apr 20, 2026
@VeryEarly
Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines
Copy link
Copy Markdown
Contributor

Azure Pipelines successfully started running 3 pipeline(s).

VeryEarly
VeryEarly previously approved these changes Apr 20, 2026
@VeryEarly VeryEarly enabled auto-merge (squash) April 20, 2026 02:43
@pranavathalye
Copy link
Copy Markdown

LGTM

Copilot AI review requested due to automatic review settings April 29, 2026 13:21
auto-merge was automatically disabled April 29, 2026 13:21

Head branch was pushed to by a user without write access

@ssubramanya ssubramanya force-pushed the dev/subramanyamn/EntraIdPowershellSupport-v2 branch from 97028e4 to e84d23c Compare April 29, 2026 13:21
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@VeryEarly
Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines
Copy link
Copy Markdown
Contributor

Azure Pipelines successfully started running 3 pipeline(s).

… CloudException catch in NewAzureSqlSyncAgent
@VeryEarly
Copy link
Copy Markdown
Collaborator

/azp run

@azure-pipelines
Copy link
Copy Markdown
Contributor

Azure Pipelines successfully started running 3 pipeline(s).

Copy link
Copy Markdown

@gouravsharmamicrosoft gouravsharmamicrosoft left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a copy of old PR which was reviewed and approved

Copy link
Copy Markdown
Member

@hareeshghk hareeshghk left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall looks good, added two comments

/// Gets or sets the identity ID of the hub database in case of user assigned identity authentication
/// </summary>
[Parameter(Mandatory = false, HelpMessage = "The resource ID of the UAMI (User Assigned Managed Identity) to use for hub database authentication.")]
public string ResourceId { get; set; }
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

here its written as resource id and also in tests but PT description says IdentityId, can you update one.
Also have you tested with latest changes of DsMainDev as few changes and new validations went into DsMainDev after your previous powershell testing

/// </summary>
[Parameter(Mandatory = false, HelpMessage = "The resource ID of the User Assigned Managed Identity (UAMI) to remove from hub database authentication." +
"If specified, this UAMI will be removed ")]
public string RemoveIdentityResourceId { get; set; }
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This about user experience, is it better to add an extra parameter like this or we only get the syncgroup and member first to receive resourceid and add a confirmation saying that "adding new UAMI will remove existing one" , just as a suggetsions, this also looks good

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants